A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
-
Updated
Dec 18, 2025 - JavaScript
A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
XSS, SQLI, LFI, RCE Practice Labs in php
With IHA089 Labs, you can practice a wide range of cybersecurity techniques, such as account takeovers, SQL injection, cross-site scripting (XSS), brute force attacks, and more. The labs are categorized into different modules, making it easier to focus on specific areas of vulnerability testing.
🔬 Advanced vulnerability testing laboratory and Vulnerable Web App & Linux Machine | Comprehensive security research environment with pre-configured vulnerable apps, automated testing scenarios, and CVE analysis | The PenTrix flagship product for professional penetration testers
A deliberately vulnerable Flask API lab built for practicing real-world API security testing — includes XSS, SQLi, IDOR, JWT flaws, and more. Perfect for bug bounty hunters, CTFs, and VAPT learners.
Integrate penetration testing tools and payloads into your workflow through the Model Context Protocol using STDIO or HTTP.
Add a description, image, and links to the vulnerable-labs topic page so that developers can more easily learn about it.
To associate your repository with the vulnerable-labs topic, visit your repo's landing page and select "manage topics."